<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: abebeos</title>
    <description>The latest articles on DEV Community by abebeos (@abebeos).</description>
    <link>https://dev.to/abebeos</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1027877%2Fe54ed92c-3ba7-40b5-8aea-74b7bd7bec83.png</url>
      <title>DEV Community: abebeos</title>
      <link>https://dev.to/abebeos</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/abebeos"/>
    <language>en</language>
    <item>
      <title>How Solana Ignores Security Best Practices</title>
      <dc:creator>abebeos</dc:creator>
      <pubDate>Thu, 16 Feb 2023 07:04:15 +0000</pubDate>
      <link>https://dev.to/abebeos/how-solana-ignores-security-best-practices-3ml3</link>
      <guid>https://dev.to/abebeos/how-solana-ignores-security-best-practices-3ml3</guid>
      <description>&lt;p&gt;I really thought "I saw it all" within crypto and open-source.&lt;/p&gt;

&lt;p&gt;But then, today, Solana managed to surprise me.&lt;/p&gt;

&lt;p&gt;I visited the project on github (&lt;a href="https://github.com/solana-labs/solana"&gt;https://github.com/solana-labs/solana&lt;/a&gt;), and tried to get an overview of the ~800 open issues and ~100 open PRs.&lt;/p&gt;

&lt;p&gt;Far too much, so I focused on the older issues, narrowed it further down to &lt;code&gt;security&lt;/code&gt; issues.&lt;/p&gt;

&lt;p&gt;To my surprise, I was... blocked:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/solana-labs/solana/issues/30328"&gt;https://github.com/solana-labs/solana/issues/30328&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Even issues like&lt;/p&gt;

&lt;p&gt;Potential privilege escalation in sys-tuner&lt;br&gt;
&lt;a href="https://github.com/solana-labs/solana/issues/9141"&gt;https://github.com/solana-labs/solana/issues/9141&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;are left open. The team maybe knows that the issues are non-critical.&lt;/p&gt;

&lt;p&gt;But a visitor cannot be sure.&lt;/p&gt;

&lt;p&gt;I guess that this is what happens after a team is successful financially: they simply do as it pleases them, joking around when visitors (of their open-source code-base) have concerns.&lt;/p&gt;

&lt;p&gt;So disappointing all this.&lt;/p&gt;

&lt;p&gt;Still need to find a smart-contract platform where the core-devs have kept some (technological, procedural) sanity, despite their financial success.&lt;/p&gt;

&lt;p&gt;.&lt;/p&gt;

</description>
      <category>solana</category>
      <category>security</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
